Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Kamasers

98
Global rank
90 infographic chevron month
Month rank
62 infographic chevron week
Week rank
0
IOCs

Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.

Botnet
Type
Unknown
Origin
1 August, 2025
First seen
20 August, 2026
Last seen

How to analyze Kamasers with ANY.RUN

Type
Unknown
Origin
1 August, 2025
First seen
20 August, 2026
Last seen

IOCs

IP addresses
48.209.138.168
158.94.208.81
48.209.138.189
135.233.95.144
88.221.169.152
40.126.32.72
23.52.181.141
128.24.231.65
23.11.41.157
2.16.241.207
204.79.197.203
2.16.164.72
74.178.240.51
172.211.123.248
2.16.241.205
48.209.133.15
74.179.77.204
88.221.169.205
40.126.29.11
48.192.1.65
Hashes
6dbd6a0cfcf749fc7aef3f828acdff16b148eeafe0cc42a9a3bbd87b07470f83
98e4f904f7de1644e519d09371b8afcbbf40ff3bd56d76ce4df48479a4ab884b
1b7a6afb58ce9d1ab0dd41e566d637dbc98647399002c198af5943c6f362a794
08b3bef1c6717c6e5a284e2b6dae47598dd8dd8521626306b490da0b0bba8441
e98f7626310221213846db81efe62d891e1445efac2ba816e3bfacb206a5e26b
51838f13f7572490a44124dc74479c10f0bcc130ae60b2fa2020a2f990447d7a
95cb1c8fd44e767c9f24c823ded9b242376b87bd37874f2e3b13c94231860481
1a590d488148de71f5d962314e2b517da3f0174e7296dad18af684ec1d819523
db8ce34cefcc83edd0e245844f35373828004706eb41f952ad0c2522e10e4b9c
3bb3f04dcac65dd07b4fd15b3ac408e447a67f634efb2ddfa557a384bcd28b45
24e32ef97f026275a324082142b1f7a7ddd0b07c0eaccb6974efcd8b422324c1
eeff7670a72ad09a45c715cdd4c6f882d42a8d9c349194009503ac14a4144a0c
80ab140086e53ea80d59a872c1ea201781d7a3eb5222ce6e1c123e39d91e542b
5f824cce1a37d2bea3adaeff27a9c29a676b3df9736cfbec8094437cb2c417e2
1151f376f7b33fe34de52002cd7ffc731fec89a02bb09205ecb362b1d797ac4c
3ec59ae574589c01c611ba26289bc111c767d3ee56b1758d3df63a1600147019
2eae760012f808e47db9c9bc1a018973f77fab29d9ed86081efe8b83cd443b16
96962b71bb2165b174e6c07bd3a8a83f292d6d579b54f62df980a83bc9989808
1720c21641c115bfef53177ca219f6941b708f0dddf89a0b22b5b9d75f4207d7
6d581ca6c51f8f23c7c80f49b316b6729cd60224f015233ba7e73812aca24bc2
Domains
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
oneocsp.microsoft.com
www.bing.com
slscr.update.microsoft.com
login.live.com
ocsp.digicert.com
www.microsoft.com
activation-v2.sls.microsoft.com
google.com
crl.microsoft.com
go.microsoft.com
microsoft.com
licensing.mp.microsoft.com
gist.github.com
play.google.com
download.ccleaner.com
www.google.com
self.events.data.microsoft.com
URLs
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://158.94.208.81/pit/wp.php
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://settings-win.data.microsoft.com/settings/v3.0/waas/featuremanagement?isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&currentbranch=vb_release&accountfirstchar=&activationchannel=retail&oemmodel=dell&flightring=retail&attrdataver=186&installlanguage=en-us&osuilocale=en-us&webexperience=1&flightingbranchname=&chassistypeid=1&osskuid=48&app=cdm&installdate=1661339444&appver=&osarchitecture=amd64&defaultuserregion=244&telemetrylevel=1&osversion=10.0.19045.4046&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
Last Seen at

Recent blog posts

post image
North Korean IT Workers Scheme: Detection IOC...
watchers 391
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 1473
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 7297
comments 0

Inside Kamasers: How a Six-Mode DDoS Botnet Uses Your Own Infrastructure Against You

Key Takeaways

  1. Kamasers is a multi-vector DDoS botnet with loader capabilities that supports HTTP GET/POST floods, slowloris, TCP SYN/ACK floods, UDP floods with IP spoofing, GraphQL-targeted attacks, and TLS handshake exhaustion.
  2. By retrieving C2 addresses from GitHub Gist, Telegram, Dropbox, Bitbucket, and even the Ethereum blockchain API (Etherscan), Kamasers hides command infrastructure behind trusted services that most enterprise networks whitelist by default.
  3. Infected systems can be used to attack third parties, creating legal and reputational risk.
  4. The threat is distributed through established malware delivery chains. Kamasers arrives via GCleaner and Amadey.
  5. It is actively observed in education, telecom, and tech sectors.
  6. ANY.RUN's Threat Intelligence Lookup lets security teams hunt Kamasers proactively. Analysts can surface related sandbox sessions, pivot across infrastructure, and track emerging Kamasers campaigns before they reach their own environment.

threatName:"kamasers".

Kamasers sandbox samples found in TI Lookup Kamasers sandbox samples found in TI Lookup

  1. Because Kamasers constructs its DDR links at runtime and encrypts its C2 addresses, static analysis alone cannot confirm infection. Executing the sample in ANY.RUN's Interactive Sandbox exposes the full kill chain, from DDR queries to C2 connection, DDoS execution, and payload download, within minutes.

View analysis session

Kamasers malware analysis in Interactive Sandbox Kamasers fresh sample analysis in Interactive Sandbox

What is Kamasers Malware?

Kamasers is a malware botnet family engineered to carry out distributed denial-of-service (DDoS) attacks using a wide range of techniques. Unlike older, simpler botnets that relied on a single flood method, Kamasers combines multiple attack vectors across both the application layer (Layer 7) and the transport layer (Layer 4), giving its operators a flexible toolkit for disrupting nearly any internet-accessible target.

The malware gets its name from the User-Agent string it uses during network communication with its command-and-control (C2) server — a naming convention that abuse.ch researchers noted when the threat was first publicly identified.

Beyond its DDoS capabilities, Kamasers can function as a loader, receiving commands from the C2 to download and execute additional files, significantly elevating the risk that a single infection could lead to data theft, ransomware deployment, or deeper persistent access.

The botnet uses a Dead Drop Resolver (DDR) mechanism to retrieve C2 addresses from legitimate public services including GitHub Gist, Telegram, Dropbox, Bitbucket, and even the Etherscan blockchain API making its infrastructure resilient and its malicious traffic difficult to distinguish from legitimate web activity.

ANY.RUN has also observed a related variant named Udados, assessed to be an evolution or updated version of Kamasers, and therefore considered part of the same family.

The Evolution of Kamasers

Kamasers variants and timeline Kamasers variants and timeline

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How Kamasers Threatens Businesses and Organizations

DDoS attacks are no longer purely a technical infrastructure problem. They escalate quickly into business crises — and Kamasers is specifically designed to maximize that escalation.

Corporate infrastructure weaponized against others. The infected company becomes, unwittingly, a source of attacks, creating reputational liability, potential contractual violations, and even legal exposure depending on jurisdiction and the nature of the targeted entities.

Single infection, multi-stage compromise. Because Kamasers operates as a loader as well as a botnet, a single successful infection can serve as the entry point for ransomware, infostealers, or remote access tools.

Detection blind spots from legitimate service abuse. By retrieving C2 addresses through services that are whitelisted in virtually every corporate network, Kamasers makes it extremely difficult for perimeter defenses and network monitoring tools to flag its communications as malicious. The malware's DDR links are also dynamically constructed at runtime, meaning static analysis of the binary will not reveal them.

Escalating response costs. Once Kamasers is identified on a corporate network, the organization must investigate infected hosts, validate whether they were used as attack sources, restore systems, address potential IP blacklisting, and manage regulatory scrutiny if any data compromise is identified. These costs accumulate rapidly.

Business trust erodes before the incident is contained. If customers, partners, or ISPs observe attack traffic originating from company infrastructure, trust may be damaged before the organization even understands the scope of what happened.

Victimology: Which Industries Are Most at Risk?

Kamasers is international in scope, with observed activity in Europe, North America, and Latin America. According to ANY.RUN threat intelligence data, the sectors most frequently targeted include:

  • Education: Large attack surfaces, often under-resourced security teams.

  • Telecommunications: High-value uptime targets; DDoS attacks cause immediate revenue and service impact.

  • Technology: API-heavy infrastructure makes GraphQL and HTTP flood attacks particularly disruptive.

  • Government / Public Sector: Railnet infrastructure linked to campaigns targeting European government organizations.

  • Financial Services: Not a primary observed target to date, but loader capability raises ransomware risk.

  • LATAM businesses (general): Direct DDoS targeting observed; C2 commands in Spanish suggest regional operator presence.

How Kamasers Gets Into Systems and Spreads

Kamasers does not arrive through zero-day exploits or self-propagating worms. Instead, it relies on established malware delivery ecosystems:

GCleaner. A pay-per-install malware distribution service that purchases access from other threat actors and redistributes payloads to systems already compromised by other means. GCleaner has been linked to numerous malware families.

Amadey. A well-documented loader/botnet used extensively by cybercriminals to deliver secondary payloads. Once Amadey has infected a host, it can be instructed to download and execute Kamasers.

This means Kamasers infections typically follow prior compromises. Common initial infection vectors feeding into these delivery chains include:

  • Phishing emails with malicious attachments or links

  • Trojanized software distributed through unofficial channels

  • Drive-by downloads from compromised or malicious websites

  • Exploitation of unpatched vulnerabilities leading to initial loader installation

    Once Kamasers is deployed on a host, it connects to C2 infrastructure and begins receiving attack commands. The infected host becomes a bot node in the wider botnet. If the C2 issues a !download (or !descargar) command, additional payloads are fetched and executed, potentially spreading the compromise further within the same environment or establishing persistent access.

How Kamasers Functions

C2 Discovery via Dead Drop Resolver

After execution, Kamasers does not connect directly to a hardcoded C2 address. Instead, it uses a Dead Drop Resolver (DDR) mechanism: it sends HTTP GET requests to public services to retrieve the current C2 server address. The DDR channels used include:

  • GitHub Gist,

  • Telegram bot,

  • Dropbox-hosted file,

  • Bitbucket repository.

These links are not stored in plain text in the binary. Tthey are constructed and unpacked dynamically at runtime, defeating static analysis. The C2 address embedded in these resources is encrypted with AES-CBC and encoded in Base64.

If the first DDR channel fails, Kamasers falls back to the next in sequence. If all four channels are unavailable, it falls back to a built-in list of hardcoded backup domains. Additionally, in some observed cases, Kamasers queries the Etherscan API (api.etherscan.io) to retrieve the C2 address, leveraging public blockchain infrastructure as yet another evasion layer.

Command Processing Architecture

Once connected to the C2, the bot registers itself by transmitting its ID, current command execution status, bot version, privilege level on the infected host, C2 discovery source, and system information.

All valid commands must begin with the “!” character prefix. The bot validates this before processing. Kamasers uses a handler caching mechanism: if the previously used command handler matches the current command, the bot takes a fast path without performing a fresh lookup. Otherwise, it triggers dynamic resolution.

DDoS Attack Capabilities

Kamasers DDoS commands Kamasers DDoS commands

Sandbox Analysis of Kamasers Sample

See the detonation of Kamasers

ANY.RUN sandbox revealing Kamasers killchain in real time ANY.RUN sandbox revealing Kamasers killchain in real time

In the sandbox analysis session, we can see how a DDoS attack targets a domain:

DDoS attack targeting a domain, exposed inside ANY.RUN sandbox DDoS attack targeting a domain, exposed inside ANY.RUN sandbox

As part of the analysis, it was observed that the bot had received the !httpbypass control command, which initiates an HTTP flood attack against a specified URL with defined intensity and duration parameters. After completing the attack, the bot reported its status and returned to standby mode.

Communication between the infected host and the C2 server Communication between the infected host and the C2 server

In a number of analysis sessions (view another one), the command-and-control server was used not only to coordinate DDoS activity, but also to deliver additional payloads. Specifically, the bot received the !download command, after which it downloaded and executed a file from an external domain, then confirmed successful session completion to the C2 server:

Example of a C2 command used to download a malicious file Example of a C2 command used to download a malicious file

In some cases, the Kamasers botnet was observed using public blockchain infrastructure as an auxiliary mechanism for obtaining the C2 address. Specifically, infected hosts queried the Etherscan API(api.etherscan.io) to retrieve data containing the URL of the command-and-control server:

Querying the Etherscan API to retrieve data Querying the Etherscan API to retrieve data

View session querying the Etherscan API

After obtaining the URL, the bot connects to the C2 server and sends information about its ID, command execution status, bot version, privileges on the infected host, C2 discovery source, and system information:

Victim request to the C2 server Victim request to the C2 server

Behavioral analysis of Kamasers showed that the botnet frequently establishes connections to IP addresses associated with Railnet LLC’s ASN.

Railnet infrastructure has previously been observed in campaigns targeting both government and private-sector organizations across several European countries, including Switzerland, Germany, Ukraine, Poland, and France.

There are also documented cases of Railnet infrastructure being used to distribute other malware families, including Latrodectus, which a number of reports link to activity associated with groups such as TA577.

The current picture of Railnet activity can be quickly verified using ANY.RUN’s Threat Intelligence Lookup. Searching by ASN makes it possible to assess how extensively it is involved in malicious chains, which malware families interact with it, and how the nature of that activity changes over time:

destinationIpAsn:"railnet"

Query for RAILNET ASN in ANY.RUN’s TI Lookup Query for RAILNET ASN in ANY.RUN’s TI Lookup

How Can Businesses Proactively Protect Against Kamasers

Kamasers relies on external infrastructure to receive commands, retrieve C2 addresses via DDR channels, and download additional payloads. Early detection therefore depends on monitoring for suspicious outbound connections and newly observed infrastructure before they can cause operational damage.

ANY.RUN's Threat Intelligence Feeds deliver continuously updated, actionable indicators of compromise (IOCs) — malicious domains, IPs — directly into a security team's existing stack (SIEM, firewalls, EDR). Since Kamasers frequently routes traffic through Railnet/Virtualine ASN infrastructure, feeds that surface ASN-level and IP-level indicators give SOC teams an early signal before a host begins actively participating in attacks.

Threat Intelligence Feeds features and integrations Threat Intelligence Feeds features and integrations

Once Kamasers activity is confirmed on a host, the next priority is understanding how far the infection extends. ANY.RUN's Threat Intelligence Lookup allows analysts to search across a broad dataset of sandbox analysis sessions using structured queries.

From a single confirmed sample, TI Lookup enables pivoting to related infrastructure, identifying additional C2 servers, uncovering other malware families sharing the same ASN or delivery chain, and tracking how Kamasers campaigns evolve over time. This context is essential for distinguishing a contained infection from an ongoing, broader compromise.

Additional Protective Measures

Network monitoring and segmentation. Monitor for unexpected outbound connections to GitHub Gist, Telegram, Dropbox, Bitbucket, and Etherscan from hosts that have no business reason to access these services. Segment networks so that compromised hosts cannot easily communicate with or download files from external sources.

Endpoint protection and EDR. Deploy endpoint detection and response solutions capable of identifying the behavioral signatures of Kamasers: anomalous outbound HTTP GET requests, process injection, and execution of downloaded PE files.

Patch management. Because Kamasers arrives through loaders like Amadey and GCleaner, reducing the initial attack surface through consistent patching of known vulnerabilities is critical.

Email and web filtering. Block phishing vectors and malicious downloads that feed the delivery chains supplying Kamasers.

IP and ASN blocklisting. Use TI Feeds to maintain up-to-date blocklists covering known associated IP addresses.

Incident response planning. Prepare for the possibility that an infected host may have been used to attack third parties. Incident response plans should include external impact assessment and communication procedures for partners, customers, and legal counsel.

User awareness training: Run simulated phishing campaigns using the exact lure types TrustConnect employs: meeting invites, bid requests, tax notices, DocuSign.

Network monitoring: Alert on outbound WebSocket connections to unexpected hosts; monitor for anomalous screen-sharing or RDP-over-browser traffic patterns.

Incident response planning: Ensure IR playbooks explicitly address MaaS RAT scenarios with follow-on RMM persistence.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Kamasers demonstrates that DDoS threats have matured well beyond simple volumetric attacks. By combining multiple attack vectors, a resilient DDR-based C2 architecture that hides behind legitimate public services, a loader capability that can deliver ransomware or credential stealers as follow-on payloads, and delivery through established malware ecosystems, Kamasers is designed to cause maximum business disruption while remaining difficult to detect and attribute.

For organizations in the education, telecommunications, technology, and government sectors (and increasingly for any enterprise with internet-accessible infrastructure) Kamasers represents a credible and evolving threat. The botnet's operators appear to be actively developing it (as evidenced by the rapid language shift from Go to C and the emergence of the Udados variant), suggesting it will remain a fixture of the threat landscape.

Proactive defense, built on timely threat intelligence, behavioral sandbox analysis, and continuous monitoring of suspicious infrastructure, is the most effective response. Understanding how Kamasers operates — technically, tactically, and at the business level — is the first step in that defense.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Crypto malware screenshot
Crypto malware
miner xmrig jsminer
Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.
Read More
Adware screenshot
Adware
adware
Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Read More
Spynote screenshot
Spynote
spynote
SpyNote, also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023–2025.
Read More
Orcus RAT screenshot
Orcus RAT
orcus rat trojan
Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.
Read More
Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Roning Loader screenshot
Roning Loader
roning
RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.
Read More